HomeCybersecurity NewsCybersecurity news weekly roundup December 11, 2023
December 11, 2023

Cybersecurity news weekly roundup December 11, 2023

SAN MATEO, CA, December 11, 2023 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Brought to you by NetworkTigers.

WordPress patches POP exploit that increases website RCE attack vulnerability

WordPress has released an update that fixes a remote code execution vulnerability that could be used with another bug to “allow attackers to run arbitrary PHP code on the target website.” Version 6.4.2 remedies a Property Oriented Programming (POP) chain weakness that, while not especially dangerous, “significantly increases the overall risk for WordPress sites.” If a plugin used on a site contains a PHP object injection flaw, which some do, this POP chain weakness becomes increasingly severe. It is recommended that all users update to the latest version of WordPress as soon as possible to mitigate risk. Read more.

Genetic testing company 23andMe says hackers accessed DNA data of 7 million users

In a regulatory filing, genetic testing company 23andMe disclosed that 7 million customers were affected by a hack in October 2023. While the firm said that around 14,000 individuals had their personal data accessed by hackers, an opt-in feature that allows DNA-related relatives to contact one another was abused and led to nearly half of 23andMe’s 14-million-person customer base having their information exposed. When the breach was first disclosed in October, 23andMe stated that they believed it was due to customers reusing passwords that had already been compromised elsewhere. Since the breach, data purported to have been stolen from 23andMe has been for sale online. Read more.

Bluetooth keyboard flaw could be used to take over Android, Linux, MacOS, and iOS devices

CVE-2023-45866 is a new Bluetooth flaw relating to a “case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim.” If properly exploited, this flaw could allow a threat actor to take control of Android, Linux, macOS and iOS devices. The attack tricks a device into thinking it’s connected to a Bluetooth keyboard, allowing an outsider to transmit keystrokes to install apps or run commands. The exploitation requires no specialized hardware other than a Linux computer using a Bluetooth adapter. More details regarding this exploit are expected to be released in the near future. Read more.

Newly developed SLAM attack can steal data from AMD and future Intel CPUs

Researchers at Systems and Network Security Group (VUSec Group) at Vrije Universiteit Amsterdam have developed a side-change attack called SLAM that “exploits hardware features designed to improve security in upcoming CPUs from Intel, AMD, and Arm to obtain the root password hash from the kernel memory.” SLAM, short for Spectre based on LAM, is a “transient execution attack that takes advantage of a memory feature that allows software to use untranslated address bits in 64-bit linear addresses for storing metadata.” The technique is effective against future chips that lack “strong canonical checks.” The code and data for reproducing this attack are available on VUSec’s GitHub repository. Read more.

Disney+ scam highlights use of sophisticated new impersonation techniques

Impersonation schemes in which hackers spoof banking institutions are not uncommon. A new scam in which hackers send fake messages purported to be from Disney+ highlights a high degree of sophistication, making it very challenging to distinguish the messages from the real thing. A report from Abnormal Security describes how the attackers “went beyond typical tactics by using a sender email resembling a legitimate Disney+ address, incorporating brand colors, and personalizing subject lines and greetings.” The messages also contained no misspellings or “malware-laden attachments” and had a legitimate-looking customer service number. Abnormal did not include technical details of the campaign, but “the primary attack vectors appear to involve a combination of email spoofing/phishing, attachment-based tactics, phone-based social engineering and brand impersonation.” Read more.

iPhone users beware of fake Lockdown Mode attack

Jamf Threat Labs has issued a report highlighting a new “post-exploitation technique” that hackers can use to trick victims into thinking that their iPhone is in Lockdown Mode while threat actors carry out covert attacks. The report “shows that if a hacker has already infiltrated your device, they can cause Lockdown Mode to be ‘bypassed’ when you trigger its activation.” According to Michael Covington, vice president of portfolio strategy at Jamf, Byy tricking the user into believing that their device is operating normally and that additional security features can be activated, the user is far less likely to suspect any malicious activity is taking place behind the scenes.” Read more.

US government agencies breached by hackers using Adobe ColdFusion exploit

CISA has warned that hackers are actively exploiting a critical vulnerability in Adobe ColdFusion to breach government servers. The agency urges all government organizations to update their systems immediately, apply network segmentation, set up a firewall or WAF, and enforce signed software execution policies. The vulnerability is reported to have been used to drop malware using HTTP POST commands to the directory path associated with ColdFusion. The breaches are said to have occurred in June of this year and resulted from “outdated software.” Read more.

LogoFAIL bugs put millions of PCs at risk of secure boot bypass

A set of critical vulnerabilities that “originate in image-parsing libraries within the boot process, impacting all major device manufacturers on both x86 and ARM-based devices” in the Unified Extensible Firmware Interface ecosystem for PCs has been uncovered, according to a report from Binarly Research. Researchers discovered that embedding compromised images in the EFI System Partition or unsigned firmware update sections could allow hackers to execute malicious code during boot-up, hijacking the process. This method bypasses Secure Boot and Intel Boot Guard safety measures, making it possible for threat actors to “insert a persistent firmware bootkit beneath the OS level.” Binary researchers warn that this flaw affects “most devices worldwide.” Read more.

P2PInfect botnet found to be targeting routers and IoT devices

A new variant of the P2PInfect botnet can target routers and IoT devices, thanks to being “compiled for Microprocessor without Interlocked Pipelined Stages (MIPS) architecture, broadening its capabilities and reach.” The MIPS variant also includes some evasive functionalities as well as an embedded 64-bit Windows DLL module for Redis, allowing for the execution of shell commands on a compromised system. According to Cado Security Labs, these updates indicate “an interesting development in that it demonstrates a widening of scope for the developers behind P2PInfect.” Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

What do you think?

Popular Articles